PrivateSovereignControlled

Operational AI for
every decision.

Private AI designed to operate with your data, your systems and the way you really work.

Scroll
Sovereign

Deploy AI where your data lives

No data egress, full control. You choose the models and policies; we turn them into outcomes.

Compliance

Auditable by design

Auditable workflows, role-based access and approvals. GDPR and ENS compliance out of the box.

ROI

Prove ROI fast

Automate one core process in days and expand across systems. No lock-in: extend what you already have.

Trusted by leading organizations across regulated industries, government and mission-critical sectors
Santander Telefónica Indra Acciona El Corte Inglés Arval, BNP Paribas Group Universidad Europea Farmaenlace Health in Code English Connection MásOrange Proeduca Cotown Residelia
The platform

Your operations controlled and running on one private platform.

From construction to intelligence to governance, the complete operating system for private, operational AI inside your perimeter.

Explore the product →

Build the operation

Agents, workflows and production applications on a single foundation.

Turn data into decisions

Knowledge base, semantic layer and graphs your teams can trust.

Every decision, under control

Traceable, auditable and compliant by design, inside your perimeter.

Sector regulado
In production
“We automated a critical back-office process in days and scaled it across systems. Without moving data outside our perimeter.”
Head of Operations

Operational AI for
every decision.

Product · Platform

One platform for
intelligent business processes.

Airflows turns your organization’s knowledge, systems and rules into operations that execute: agents, workflows and applications running under your control, inside your perimeter.

The operating system for decisions

Not another chat window.
An operation that runs by itself.

Business context

Bring together the information, rules and priorities your teams need to make better decisions.

Decision flows

Turn recurring business decisions into structured processes that move from input to outcome.

Enterprise action

Connect people, systems and AI so work can be executed safely across your organization.

Operational control

Keep visibility over what happens, who approves it and how every decision moves forward.

The platform

Built to operate,
not to chat.

Agents

Agents that execute decisions.

Task-specific agents that classify, draft, validate and escalate work, with human checkpoints where it matters.

Workflows

Auditable workflows, end to end.

Model your business processes and automate them with full traceability of every step and decision.

Applications

Back-office apps in days.

Spin up production-ready apps (forms, case inboxes, document viewers) ultra-efficiently with AI.

Architecture

From source to decision.

Your systems of record stay the source of truth. Airflows orchestrates agents, workflows and apps on top of them, inside your perimeter, and returns auditable decisions.

Sources Airflows platform Operation SAP Oracle Microsoft 365 Email · Databases Private AI · under your control Governance Decision Automated action Audit & trace

Building with Airflows is this easy.

Platform modules

Everything connected
under one platform.

01

Agents

Task-specific AI agents that classify, extract, draft and escalate work automatically, with human-in-the-loop checkpoints.

Agent RuntimeAssistants
02

Workflows

Orchestrate end-to-end processes with SLAs, queues, approvals and deterministic routing across teams and systems.

OrchestrationSLAs
03

App Builder

Build production-ready operational interfaces visually: forms, inboxes, viewers and dashboards.

Low-CodeTheming
04

Integrations

Connect your systems of record via API-first and webhooks, keeping them as the source of truth.

API-firstWebhooks
05

Security

Private deployment, no data egress. Encryption, role-based access control and perimeter isolation.

RBACNo egress
06

Governance & Auditability

Every model decision is explainable and logged. GDPR and ENS compliance by design.

Audit logRGPD · ENS
07

Developer Experience

SDK, documentation and environments to extend the platform without friction.

SDKDocs
08

Observability

Real-time metrics, traces and monitoring of agents, workflows and apps in production.

MetricsTraces

Operate for less

Agents take on repetitive work end to end, so operating cost falls without cutting capacity.

From months to days

Production-grade apps and workflows ship in a fraction of the usual time.

Compliance, no trade-offs

Every decision is private, traceable and auditable by design, ready for your regulatory framework.

Integrations

Integrates with your
existing tools.

Connect to SAP, Oracle, Microsoft 365/SharePoint, Salesforce, ServiceNow, document repositories, email and databases. Trigger actions through webhooks/APIs and keep your systems of record as the source of truth.

SAP

SAP

Integrate ERP data and workflows seamlessly.

Oracle

Oracle

Databases and cloud services for data management.

Salesforce

Salesforce

Sync customers, leads and sales flows.

ServiceNow

ServiceNow

Automate ITSM and business processes.

Microsoft 365

Microsoft 365

Office, Teams and cloud services integrated.

SharePoint

SharePoint

Documents, lists and collaboration.

Google Sheets

Google Sheets

Google Workspace spreadsheets.

Gmail

Gmail

Secure, efficient email communication.

OpenAI

OpenAI

Advanced models like GPT-4 for AI capabilities.

People in control

AI operates.
Your organization stays in control.

Airflows automates the repetitive work and surfaces the decision that matters, with the human checkpoint exactly where your organization needs it.

Ready to build?

Solutions

Specialized solutions
for your industry.

Pick a starting point and get pains, quick wins and architecture at a glance, by industry or use case.

By use case

Common challenges solved with AI.

Invoice processingExtraction · validation · posting
Contract managementReview · redlining · renewals
Approval workflowsQueues · SLAs · routing
Document classificationTagging · auto-routing
Compliance reportingAudit · traceability · evidence

Find your starting point.

Case studies

Find the project
that suits you best.

Explore some of our work and discover how the platform has transformed various industries.

Banca
Banking & insurance · Contract management
“We automated document review and scoring with full audit of every decision. We went from months to weeks.”
CTO, financial institution
Public administration · Processing
“Traceability gave us the confidence to deploy AI in real procedures, without moving data outside our perimeter. Citizens notice it.”
Director of Digital Transformation
Administración pública
Industria
Industry · Invoice processing
“Automatic extraction and posting of invoices, with human-in-the-loop where it matters. 80% less hidden cost.”
Head of Operations
Use cases

Common challenges, solved.

Documents

Invoice processing

Automatic extraction, validation and posting with human oversight.

Contracts

Contract management

Guided review, redlining and renewal control.

Compliance

Compliance reporting

Audit, traceability and evidence ready for the regulator.

Your case, next.

Solutions · Public sector

The future, today, for public administration.

Trustworthy, sovereign and traceable AI in service of citizens. We modernize public management without losing control of data.

Edificio institucional
Citizen attention

Public assistants

24/7 resolution of procedures in natural language, smart routing and answers verified against current regulation.

Files

Smart processing

Automatic classification, extraction and prioritization of files. Cuts times while keeping human oversight.

Policy

Impact analytics

Simulate and evaluate the effect of public policies on real data before implementing them.

Sovereignty

Data under control

On-premise or sovereign-cloud deployment. ENS, GDPR compliance and full audit of every model decision.

Transparency

Full traceability

Every system output is explainable and logged. Accountability by design.

Interoperability

Integration with legacy systems

Connect to existing registries and platforms without mass migrations or service downtime.

Files that move forward

Administrative work is resolved in a fraction of the time, without losing guarantees.

Decisions that withstand an audit

Every resolution is explained and traced, ready for oversight.

Attention that never closes

Citizen service responds continuously, with no queues or office hours.

Customer stories

Operational workflows the public sector modernizes first

Explore some of our work and discover how our platform has transformed public-sector operations.

ANH
Energy · Data

ANH: Extract intelligence from your geophysical reports

Automated data extraction and AI-powered semantic search so your engineers make precise decisions, without slow, error-prone manual reviews.

  • Automatically extract data from unstructured sources with no manual effort
  • Query geophysical data in plain language through an AI assistant
  • Free up engineers and analysts to focus on high-value decisions
Ministerio del Interior
Security · On-premise

Ministerio del Interior: AI that never leaves your perimeter

Deploy powerful AI applications in fully isolated, air-gapped environments, no internet connection required, no data ever leaving your infrastructure.

  • Run AI models fully on-premise, with zero exposure to external networks
  • Meet the strictest compliance and data sovereignty requirements across regulated industries
  • Keep sensitive operations (defense, energy, finance) fully secured and auditable
Public sector

Let’s modernize the public sector,
together.

Government & Defense · Public sector

CPI · Intelligent Public Procurement.

Private, sovereign and governed AI for the entire public procurement cycle. Files audited against the LCSP in seconds, with human oversight and traceable evidence end to end.

CPI is the Airflows suite that applies private, sovereign AI across the entire public procurement cycle. It covers three use cases on a single platform (drafting tender documents, managing files and evaluating bids) so the Administration gains efficiency without giving up control of its data or the final decision. A single, ready-to-run solution that offloads the team and keeps every step traceable.

The solution

What CPI does.

01

From blank page to a tender ready to publish

CPI turns the need into a structured tender: it defines subject matter, CPV, budget and coherent criteria, and drafts the PCAP and PPT from your templates and precedents. It also validates LCSP compliance and flags the clauses with the highest risk of appeal, so the file is defensible from the very first version.

02

Less administrative burden, more files resolved

CPI reads, classifies and structures the file's documentation, extracting key information such as subject matter, CPV, amounts, award criteria, solvency and associated documents. It audits calculations, taxation and fraud risks before approval, and keeps human oversight where it matters. This reduces manual work and speeds up the procedure.

03

Every score, anchored to its evidence

CPI normalizes each bidder's proposals, applies the tender criteria (value judgment and formula) and anchors every score to the specific evidence in the proposal. It generates a weighted ranking and a reasoned award report, with criterion → evidence → score traceability ready to hold up against appeals.

How it works

From the official repository to the verdict, in one continuous flow.

The system connects to the Public Sector Procurement Platform (PLACE) and downloads files automatically and continuously, in the standard CODICE format (the Spanish profile of UBL 2.1). The download is parameterizable (start date, incremental or full mode, pausable without losing progress) and every run is logged: entries processed, files created or updated, status. Any month can be reprocessed.

Alongside each file, its documents are downloaded, PCAP, PPT, Justification Report. A document-extraction agent reads the PDFs and structures their content: subject matter, CPV, amounts, award criteria with their formulas, required solvency, clauses. In the same process, the full content is indexed for semantic search. Manual upload is also supported: a reviewer can upload a tender document before its publication on PLACE and audit it with the same flow.

When a file comes in, the audit workflow is triggered automatically:

Legal verification

That award criteria add up to exactly 100 points; that taxation matches the territory (IVA, IGIC or IPSI); that the required economic solvency respects the limit of Article 87 of the LCSP; that the document contains all mandatory clauses. Each breach generates an alert with its criticality level.

Split-contract detection

The system cross-references the awardee against the full PLACE history. If the sum of minor contracts per company, body and year exceeds the legal thresholds (€40,000 in works, €15,000 in the rest) it raises a red flag.

Evaluation

With no critical alerts or red flags, the file is approved automatically. With them, the process moves on to human review.

The system generates the audit report in three sections: economic, legal (LCSP compliance article by article) and technical (split-contract analysis). And it goes one step further: it produces a Version 2 of the PCAP and PPT with the proposed corrections marked on the document itself, like tracked changes. The drafter receives exactly what to change, where, and why.

Two automatic emails: to the technical reviewer, with the alerts ordered by criticality and the report attached; to the document drafter, with the corrected documents. The reviewer validates from the file's record, with a viewer that jumps to the exact paragraph where each issue was detected, and approves or rejects. The final decision is always human, and it is recorded.

Airflows panel: amounts per file, by contract type and top awardees
The analytical assistant

Expert agents 24/7 for any query.

Teams query the entire history in natural language. The assistant generates charts directly from the data (amounts per file, per contract type, per awardee) searches inside the tender documents' content ("which files include late-delivery penalty clauses?") and returns the exact citation with a link to the record and the paragraph in the document. And it understands the domain: it knows what the Estimated Contract Value is, how it is calculated and which LCSP article regulates it.

Contract broken down into entity, procedure, CPV, amount, term, obligations and LCSP regulation
The semantic layer

Your operations and your legal framework, modeled in a knowledge base. Ready for AI to reason over.

The data model is aligned with the eProcurement Ontology (ePO), the European Union's official semantic standard for public procurement. Agents don't know the meaning of each field because someone wrote it in a prompt: they know it because it is defined in the ontology, with the legal semantics of the LCSP. That knowledge is reusable, auditable and aligned with the European standard used by member states' procurement platforms. It is the knowledge base that turns every file into operational intelligence for the Administration.

Privacy, control, sovereignty

Private, sovereign and governed AI.

Privacy

Data remains protected within the organization's environment.

Control

Governance, access and traceability: every verification, alert and validation is recorded.

Sovereignty

Deployment on your infrastructure or sovereign cloud: data and models remain under your jurisdiction.

Indicators

System performance indicators.

100x

analysis speed per file

100%

file analysis coverage

<1 min

average analysis time per file

Natural-language query returning the exact citation of article 193 of the LCSP
Beyond procurement

The tool that adapts to your processes.

The same architecture (ingestion from official sources, document extraction, agent-driven audit workflow, analytical assistant and semantic layer) applies to sanction files, fleet and equipment control, personnel management or any domain with multiple data sources and a need for continuous audit.

Take-away

The whole cycle, under your control.

A single sovereign platform for all procurement: from tender to award, without taking data out of the Administration’s environment and with the human decision always at the center. CPI doesn’t replace your team: it offloads it, shields the file and makes every decision traceable and defensible.

Procure better, faster
and with greater assurance.

Every file is processed with AI, validated with human control and backed by traceable evidence end to end.

Operational AI for Every Decision
Government & Defense · Public sector

Urban digital twin.

See the city live, decide on the map and act: all in one model.

A city generates millions of data points every minute (fleets in motion, cameras, stations, incident reports) yet deciding still depends on systems that don't talk to each other and on the memory of whoever is on duty. The urban digital twin turns that territory into a single living model on Airflows: every vehicle, base, sensor and alert on the same operational map, understandable and actionable. It is not a dashboard to watch the city; it is the environment where you decide and act on it, private, sovereign and under the administration's control.

The model

The city, turned into data.

01

The city’s territory, turned into data

The starting point is not a generic map: it is the real city (districts, road network, infrastructure) loaded as the twin’s foundation. Every operational layer lives on that same map, ready to be queried or activated.

02

The city now measures itself

Traffic, cameras and stations stop being isolated sources and start feeding one single model. The twin doesn’t wait for the report: it senses the state of the city in real time and keeps it up to the minute.

03

Know what you have and where it is

Every base, vehicle and material resource, with its location and status kept current. When the call comes in, the question “what do I have available, and where?” is already answered, before deciding.

Use cases

From the alert to the action, on the same map.

01

Entity dispatch: From the alert to the resource, assigned on the map

When an alert comes in, the twin identifies the most suitable resource and assigns it on the map: with its route, estimated time of arrival and priority. What used to be a chain of phone calls becomes a traceable decision in seconds.

02

Scenario simulation: Simulate before committing resources

Before moving a single resource, the twin simulates the scenario on the real city: how it evolves, which access routes get cut off and what needs to be mobilized. It works for a fire, a flood or a weather alert: you decide on the scenario, not on intuition.

03

Workflows · Alert management: Every alert becomes a process

An alert is not a notice that resolves itself: it is a process with detection, escalation and resolution. The twin models it as a governed workflow, so nothing depends on someone remembering the next step.

The same engine beats in all three: AI agents that query the twin, decide with the rules of the domain and act within their permissions, with every step traced.

How it works

Underneath every action, agents with permissions.

Every step is executed by an agent with its own tools and its own limits.

The twin detects or receives the alert: a sensor, a camera, a manual report.

The agent queries the semantic layer: what exists, where it is and in what state.

It applies the rules of the domain (priority, availability, coverage) to choose the resource.

It executes (dispatch, alert, escalate) only within the tools and limits assigned to it.

Every step is recorded: which agent decided, with what data and why.

Twin detail: an incident with its resources and live camera
The semantic layer

The semantic layer is the model of the city.

Underneath everything there is a semantic model: the city’s entities, how they relate and the rules that govern them. That is what gives meaning to the data, an ambulance is not a point on the map, it is a resource with a state, a base, coverage and priority. On top of that model, the twin and its agents can reason and decide, not merely represent.

01

A single operational picture where there used to be systems that didn’t talk to each other.

02

From observation to action without leaving the platform.

03

Every decision, traceable: which agent, with what data and within what limits.

Take-away

The whole city, in front of whoever decides.

The urban digital twin does not replace the person who decides: it puts the whole city in front of them, understandable and in real time, with action one click away. The same intelligence the city was already generating, finally turned into a decision, and into action.

See the city live,
decide on the map.

Observation, decision and action in the same model, private, sovereign and under the administration’s control.

Operational AI for Every Decision
Free assessment · 18 questions

Operational AI Adoption Index.

Find out where your organization stands on operational AI, and what is holding it back.

You see the result straight away: no waiting for anyone to call you.

Between 6 and 8 minutes.

What you get

Your result, on screen.

01

A score out of 100

And the maturity level it corresponds to, so you can place your organization at a glance.

02

Your profile across six areas

Use, processes, data, technology, governance and people, where you are solid and where you are not.

03

The constraint holding you back

The area that is limiting all the others, and why moving it first changes the whole picture.

04

Where to start

A use case that fits your situation, with the first concrete step.

It works for public administration, for large organizations in regulated sectors and for smaller companies, the questions adjust to the type of organization.

Find out where you stand.

You see the result straight away: no waiting for anyone to call you.

Paso 1 de 4

First, four questions with no typing.

They decide which questionnaire you see and which organizations you are compared with. No personal data yet.

Your result is ready.

Two fields, nothing else. No phone number.

0/ 100

Breakdown by dimension

Main constraint

Recommended first use case

Next steps

The comparison with equivalent organizations is not shown yet: until there are enough comparable organizations there is no comparison, and we are not going to invent one.

Review it with a specialist
Inside · Resources & Partners

Learn, download, deploy.

Documentation, courses and training to master Airflows like a pro, and a partner program to grow together.

Training & documentation

Everything there is to know
about Airflows.

Whitepaper

The business case for operational AI

How to quantify the return of AI beyond the pilot.

Download →
Guide

AI in government: from ENS to production

Practical framework for compliance, sovereignty and traceability.

Download →
Brand kit

Logos, colors and usage

Download the Airflows brand kit.

Open kit →
Partners

Join the Airflows partner network

Access training, documentation, certifications and new markets.

Become a partner →
Inside · Blog

AI ideas that
actually execute.

Product, applied engineering and sector learnings, no fluff.

← Back to blog

From assistant to operational AI: the leap that really matters.

Most organizations have already tried AI. They’ve opened a chat window, asked questions and seen plausible answers. And there, almost always, they stop: at the demo. The assistant impresses, but it doesn’t execute real work.

The leap that really matters isn’t conversational, it’s operational. It happens when AI stops answering and starts doing: classifying a file, extracting invoice data, drafting a document, escalating an exception to the right person, and leaving a record of every step.

Why pilots stall

An AI pilot usually dies for three reasons: the data lives in systems the model can’t touch, there’s no way to audit what it decides, and the return never reaches production because every new case requires rebuilding everything.

  • Data is trapped in ERP, ECM and BPM that nobody wants to replace.
  • Without traceability, no leader signs off a real deployment.
  • The demo doesn’t scale: what works for one case doesn’t serve the next.
AI only transforms when it stops being a technical project and becomes an everyday tool.

What changes with operational AI

Operational AI starts from a different premise: your systems of record stay the source of truth, and AI operates on top of them, inside your perimeter. Agents execute tasks with human-in-the-loop checkpoints where it matters, workflows orchestrate the process end to end with SLAs and approvals, and every decision is logged and explainable.

The result is measurable from the very first process: less hidden cost, more delivery speed and compliance that isn’t an add-on, but part of the design.

The practical path

Start with a critical back-office process, automate it in days while keeping human oversight, prove the return and expand to other systems. No lock-in, no replatforming, without moving data outside your house.

Ready to move from pilot
to production?

News & press

Airflows in the media.

Product announcements, company milestones and press appearances.

Funding · June 2026

Airflows raises €2M from Adara Ventures and Armilar.

AI in the enterprise cannot be a black box. It has to be private, governed, controllable and predictable. That’s what we’re building: AI companies can actually operate in production, across applications, workflows, processes and agents. Because enterprise AI is not about the best demo; it’s about trust, control and real-world deployment.

Read on LinkedIn →
10 ABR 2026

Airflows scales its private AI platform in regulated sectors

The company accelerates its expansion across enterprise and public administration.

22 MAR 2026

New native integration with SAP and ServiceNow

More API-first connectors to orchestrate processes over your systems of record.

14 FEB 2026

Airflows strengthens its governance for ENS compliance

Audit and traceability of every model decision, by design.

30 ENE 2026

Back-office case: 80% reduction in hidden cost

Results from one of our most notable deployments.

Brand kit

Download our logos, colors and usage guidelines.

Open brand kit →
Inside · Company

The people behind
the platform.

A team that combines product engineering, applied AI and deep sector knowledge.

Antonio Lillo
Antonio LilloCEO & Co-founder

25 years leading technology, strategy and business development at companies focused on Digital Transformation.

Ignacio Cabrera
Ignacio CabreraChairman & Co-founder

Serial entrepreneur with 30 years launching and scaling technology startups.

Eduardo Rivas
Eduardo RivasCRO & Co-founder

25 years leading business and technology teams, transforming companies through the intelligent use of their data.

Paco Hernández
Paco HernándezR&D&i & Co-founder

25 years directing large engineering teams and defining the technical architecture of major companies' digital products.

Julio Casal
Julio CasalCo-founder

Serial entrepreneur with 30 years launching technology startups and guiding them on their path to Silicon Valley.

Track record

Founders of successful companies.

Datio Paradigma Stratio Wazuh Constella Intelligence AlienVault Overview Effect
Our vision

“Operational AI, private and under your control. Built for how your organization actually works.”

Airflows is born from a conviction: AI only transforms when it stops being a technical project and becomes an everyday tool. We build so any organization, large or small, private or public, can access that capability, without giving up control of data.

Get a demo

Private AI for
your operations.

Tell us your case and we’ll show you how Airflows solves it. We reply in under 24h.

Oficinas de Airflows, sede en Madrid We reply in under 24h
← Back to blog

New Airflows UX and UI.

Nueva interfaz de Airflows

We rebuilt the Airflows look & feel to guide every user with confidence: a full visual refresh, tighter performance, and a friendlier on-ramp through new wizards.

UI best practices everywhere

We applied modern UI heuristics (predictable spacing, strong contrast and simplified hierarchies) so people can find, decide and act faster.

  • Consistent component sizing and focus states to reduce ambiguity.
  • Clear empty states and inline hints to cut friction on first use.
  • Readable typography scale with generous line-height for long sessions.

Guided wizards that lower the learning curve

New step-by-step wizards walk users through critical flows (setup, data connections, model publishing) so teams ship value without steep ramp-up.

  • Contextual tips per step to prevent dead-ends and rework.
  • Smart defaults informed by common industry patterns.
  • Progress checkpoints with undo-friendly actions.
A cohesive look & feel, UI best practices, brand cues and guided wizards now work together to shorten the path from idea to outcome.

Brand-led navigation that orients you

We leaned on Airflows’ visual language (color, iconography and micro-interactions) to help users recognize areas instantly and build spatial memory across the platform.

  • Section theming aligned with the Airflows palette so you always know where you are.
  • Icon cues paired with concise labels for faster scanning.
  • Motion tuned to be informative, not distracting.

WCAG-first redesign

Contrast, focus order, landmarks and keyboard paths were audited to align with WCAG best practices, improving accessibility for all users.

  • Higher contrast tokens for text, controls and interactive states.
  • Visible focus rings and logical tab order across critical flows.
  • ARIA labels and semantic structure on key templates.

Lean static assets, faster loads

We optimized and consolidated static assets, reducing payload size and improving response times, especially on first paint.

Want to see the new
experience live?

← Back to blog

Enhanced GIS Viewer.

Visor GIS de Airflows

Airflows GIS now handles rich entities, layered views, time controls, live data and AI-first exploration, from single-point maps to full geospatial canvases.

Beyond single points

In 2.1, any entity can be marked Geospatial and added to richer GIS visualizations, no longer limited to a single point layer.

  • Multiple layers with on/off visibility toggles.
  • Custom styling per layer for clarity and brand fit.
  • Support for points, lines, polylines and polygons, any GIS element is welcome.

AI-first exploration

Integrated with Airflows agents so teams can query, summarize and correlate spatial data in plain language.

  • Ask for hotspots, anomalies or trends without writing GIS queries.
  • Agent-guided filters to focus on what matters.
  • Explainability baked in: how results were derived and what changed.
Layered maps, AI-first exploration, temporal playback, live monitoring and enterprise exports, all while keeping performance lean.

Temporal & live views

Scrub through time to see how entities evolve, or switch to Live Mode to monitor changes as they happen.

  • Time sliders to pick the exact moment you need.
  • Real-time updates for operational monitoring.
  • Layer-aware playback so each dataset respects its own cadence.

Precision tools & export

Measure areas and distances with built-in tools, then export your views to share or archive.

  • Area and distance measurement overlays.
  • Export snapshots or data for downstream analysis.
  • Full on-prem support for air-gapped environments.

Put your data
on the map.

← Back to blog

Finetune LLMs faster with curated corpora and full traceability.

Constructor de corpus de Airflows

We’ve added the ability to train and tune your own model on the Airflows platform: pick your data, clean it, enrich it, and ship models with minimal time to market.

Curate the right corpus

Select exactly which elements belong in your corpus, then prune, edit or enrich them manually or automatically.

  • Source selection with filters and quality checks.
  • Manual and automated enrichment paths.
  • Quick removal of noisy or stale data.

Traceability end-to-end

Track every corpus change, training run and generated model with audit-ready logs.

  • Versioned corpora and training metadata.
  • Lineage from dataset to model artifact.
  • Rollbacks with confidence.
Curate, trace and ship custom models with rich corpus control, strong lineage and the flexibility to choose the right foundation every time.

Broad model palette

Fine-tune on the models that fit your use case: Bloom, Falcon, Gemma, GPTOSS, Llama, Mistral, Phi, Qwen and more.

  • Pick architectures by latency, cost or license.
  • Swap baselines without reworking pipelines.
  • Benchmark variants with side-by-side evals.

Minimal time to market

Prebuilt flows accelerate data prep, training and deployment so teams deliver in weeks, not quarters.

  • Opinionated defaults for common industries.
  • CI-friendly hooks to automate retrains.
  • Safe rollout with canaries and quick rollback.

Train your own
model with Airflows.

Solutions · Banking & insurance

Risk decisions fast and auditable.

Automate document review, scoring and compliance with full audit of every decision, without moving data outside your perimeter.

Challenges
  • Slow, manual document review.
  • Regulatory pressure and audit needs.
  • Sensitive data that cannot leave.
Quick wins
  • Automatic document extraction and validation.
  • Explainable, traceable scoring.
  • GDPR compliance by design.
Use cases

From file to compliance.

Onboarding

KYC / AML

Document verification and automatic checks, with human escalation on exceptions.

Risk

Credit scoring

Custom models on your context, with every decision explained and logged.

Claims

Claims handling

Automatic classification and prioritization to resolve the urgent first.

Earn trust in every conversation

Precise, confidential and empathetic answers that strengthen customer confidence at scale.

Deliver error-free responses

In financial services a mistake can cost a customer for life; AI delivers instant, accurate and compliant support.

Guide complex journeys

From onboarding to loans, claims and disputes, with full-context handoff to a person when needed.

Customer stories

Operational workflows banking teams modernize first

Explore some of our work and discover how our platform has transformed banking operations.

Banco de Fomento
Documents · Agents

Banco de Fomento: Intelligence built into every document

Structured access to unstructured data, AI agents that surface the right information from transaction reports and client files, instantly and on demand.

  • Transform voluminous, unstructured records into searchable applications
  • Deploy AI agents that locate critical data to your teams in real time
  • Eliminate intensive review across client files, reports, and operational records
Minsait
Platform · Time-to-market

Minsait: A full factoring platform, shipped on your timeline

A production-ready product delivered at a speed and cost no conventional approach could match.

  • Compress development cycles with AI-powered tooling without sacrificing quality
  • Deploy a white-label solution ready to roll out across your client portfolio
  • Ambitious delivery windows, out of reach with conventional development stacks
Banking & insurance

Risk under control,
faster decisions.

Solutions · Healthcare

Less admin burden, more clinical time.

Clinical document management and administrative processes with privacy by design, so teams focus on the patient.

Challenges
  • Fragmented clinical documentation.
  • Strict privacy and consent.
  • Admin tasks that steal time.
Quick wins
  • Structured extraction from reports.
  • Privacy by design, data under control.
  • Automation of administrative circuits.
Use cases

From document to care.

Patients

Administrative attention

Assistants that handle appointments and procedures, freeing staff.

Documentation

Clinical reports

Structures and summarizes documentation with traceability and privacy.

Compliance

Consent & GDPR

Access controls and logging of every use of sensitive data.

Less admin, more care

Teams reclaim hours from paperwork to spend on the patient.

Every record, traced

Clinical information is governed with full traceability and compliance by design.

Care that never rests

Continuous support for patients and professionals, at any time.

Customer stories

Operational workflows healthcare teams modernize first

Explore some of our work and discover how our platform has transformed healthcare operations.

HealthInCode
Clinical data

Clinical data structured from the source

An interoperable taxonomy platform that standardizes heterogeneous clinical data at intake, so analysis, decisions, and compliance are built on a single reliable foundation.

  • Collect and structure clinical information through intelligent, standardized intake interfaces
  • Unify fragmented clinical datasets into an interoperable, audit-ready structure
  • Accelerate decision-making with clean, contextual data available across every care team
Healthcare

Technology in service
of the patient.

Solutions · Utilities / Infrastructure

Critical assets, operated with intelligence.

Predictive maintenance and critical-asset operations combining IoT data and custom models, with human oversight.

Challenges
  • Costly unplanned downtime.
  • Scattered IoT data without context.
  • Distributed assets hard to monitor.
Quick wins
  • Predictive maintenance on IoT signals.
  • Early anomaly detection.
  • Operations with human oversight.
Use cases

From signal to action.

Maintenance

Predictive

Anticipate failures and plan interventions before breakdown.

Operation

Monitoring

Dashboards that update instantly across your assets.

Efficiency

Optimization

Tune consumption and resources to real demand.

Fewer unplanned stops

The operation anticipates incidents before they halt service.

From signal to action

Field signals are analyzed and turned into operational decisions in real time.

Traceable operation

Every action is logged and auditable end to end.

Customer stories

Operational workflows utilities & infrastructure teams modernize first

Explore some of our work and discover how our platform has transformed utilities and infrastructure operations.

Acciona
Sustainability

Acciona: Sustainability impact, made visible and verifiable

A dynamic platform that publishes sustainability initiatives to the public in real time.

  • Publish sustainability projects through a visual portal
  • Onboard new initiatives quickly through an agile management layer
  • Bring real value of sustainability work to the public
Arval
Mobility · Real time

Arval: Smarter mobility costs in real time

A high-performance configuration and calculation engine that lets clients instantly model their mobility costs, built to handle the scale of a major national campaign.

  • Give clients a visual, intuitive tool to configure and compare mobility scenarios
  • Run complex cost calculations in real time, powered by a robust backend interaction layer
  • Scale seamlessly under high traffic without compromising speed or user experience
Utilities / Infrastructure

Critical infrastructure,
always running.

Solutions · Industry / Telco

Plant and network processes, truly automated.

AI automation of plant and network processes, keeping human oversight where risk demands it.

Challenges
  • Repetitive manual processes.
  • High volume of incidents.
  • Legacy systems hard to integrate.
Quick wins
  • End-to-end process orchestration.
  • Automatic incident classification and routing.
  • Integration with legacy systems, no migration.
Use cases

From incident to resolution.

Plant

Process automation

Workflows that run repetitive tasks with human oversight.

Network

Incident management

Automatic classification and routing to resolve faster.

Quality

Quality control

Real-time detection of defects and deviations.

Processes that fly

Critical flows resolve at a speed manual work can't reach.

Less manual work

Agents take on repetitive tasks and free teams for what adds value.

Full traceability

Every process is documented and ready for audit and compliance.

Customer stories

Operational workflows industry & telco teams modernize first

Explore some of our work and discover how our platform has transformed industry and telco operations.

+Orange
Compliance · Governance

+Orange: Gift compliance, controlled end to end

A centralized gift management platform with a built-in rules engine, so every interaction is tracked.

  • Enforce spending thresholds automatically with configurable rules
  • Route approvals through hierarchical review flows
  • Immutable audit trail that satisfies regulators and compliance teams
Universidad Europea
Education · Review

Universidad Europea: half the time, twice the accuracy in reviews

An AI platform that reads, extracts, and routes academic programme documents, cutting cycles by 50% while keeping control.

  • Extract student outcomes and impact from lengthy academic reports
  • Automatically assign documents to the right reviewers via a BPM engine
  • Reduce error-prone manual validation while keeping faculty sign-off as the final gate
Industry / Telco

Plant and network,
operated with AI.

Company · Partners

Grow with Airflows.

Join an ecosystem of technology, implementation and channel partners building private, operational AI for regulated industries and the public sector.

Our partners

An ecosystem that delivers.

Technology, implementation and channel partners building private operational AI together with us.

Now available on Google Cloud Marketplace

Deploy Airflows directly from your Google Cloud account, with consolidated billing.

Available onGoogle Cloud Marketplace
Partner tiers

Three ways to partner.

Technology

Technology partners

Integrate your models, connectors or data products with the Airflows platform.

Implementation

Implementation partners

Deliver and scale Airflows projects with certified teams and shared methodology.

Channel

Reseller & channel

Bring private operational AI to your market with commercial and enablement support.

How to join

From application to delivery.

01

Apply

Tell us about your company and focus.

02

Enable

Access training, documentation and certification.

03

Build

Develop and validate your first joint solution.

04

Grow

Go to market with commercial support.

Let’s build together.

Join us

We build AI that
actually runs.

No demos, no pilots that die in a slide deck. Our software runs inside ministries, banks and critical infrastructure, with real people depending on it every day.

45+clients in production 2open roles Madridhybrid
What it’s like

Small team. Serious problems.

What you build, ships

In weeks, not quarters. With real users on the other side telling you whether it works.

You work with agents, not against them

AI agents are part of the daily flow. Your value is in deciding and validating, not typing.

Sectors where failure isn’t an option

Defense, public administration, banking, healthcare. If it can’t be audited, it doesn’t ship.

Flat team, high judgement

Few layers, lots of autonomy. If something is badly framed, you say so and it changes.

Several organizations from the inside

In two years you’ll have seen how software gets built in very different places. Few people gain that perspective so fast.

Our own product, a category still being built

Operational AI is a market being written right now. There’s room to shape how.

Airflows team working at the Madrid office
Straight talk

What this is not.

We’d rather you find out now than in the third interview.

  • Not a research lab. You won’t be fine-tuning models or publishing papers.
  • Not a consultancy that places you somewhere and forgets about you. You’re on our payroll, with a team behind you.
  • Not a single-technology job. If you want three years in the same framework, this isn’t it.
  • Not a place where AI-assisted development is up for debate. It’s how we work.
The process

Four conversations. No games.

  1. 01

    First chat

    30 minutes to see if it makes sense for both sides.

  2. 02

    Technical interview

    An hour on architecture and design decisions, based on your own real projects.

  3. 03

    Practical exercise

    Bounded, with AI agents allowed and encouraged. We care how you direct them and what you discard.

  4. 04

    Final conversation

    Fit, expectations and terms. No surprises at the end.

Airflows in short

Operational AI for regulated sectors: private agents, auditable workflows and business apps that run on the client’s infrastructure.

  • +45clients in Spain and LATAM
  • Madridhybrid, one team
  • ENS ALTAcertified platform
  • 6regulated sectors

Come build it with us.

← All open roles Open role · Engineering

Forward Deployed
Engineer.

Madrid Hybrid Full-time Client-facing

Go into the client’s operation, understand how it really works, and get AI running on the systems they already have.

The role

An Airflows Forward Deployed Engineer doesn’t wait for the requirement to arrive in writing. You go into the client’s house (a ministry, a bank, a telco) sit down with whoever runs the process, understand how it actually works, and get AI executing it on the systems they already have.

It’s an engineering role with the business people in the room. Half the work is technical; the other half is understanding a real operation, with its exceptions, its internal politics and its regulatory constraints.

What you’ll do

  • Sit down with the business, understand the process and translate it into an architecture that holds up in production.
  • Build on the Airflows platform: agents, workflows, back-office applications and the governance layer.
  • Work on the client’s own stack when that’s what’s needed: their language, their databases, their pipelines, their standards.
  • Integrate with their systems of record (SAP, Oracle, Microsoft 365 and SharePoint, Salesforce, ServiceNow) via API and webhooks, without replatforming.
  • Deploy and operate in client environments: on-premise, private cloud, installations with connectivity restrictions.
  • Hold the technical conversation in front of a head of IT: knowing how to ask, and how to say no.

What we need from you

  • Experience building production software, with ownership of what you shipped.
  • Solid backend and enough frontend fluency to close a complete feature on your own.
  • The ability to enter a stack you didn’t know and be useful within days. This matters more than mastering one specific technology.
  • Direct client contact and tolerance for ambiguity: here the requirement is discovered, not received.
  • Everyday use of AI agents in your workflow, with concrete examples of what you’ve built that way.
  • Spanish and technical English. Availability for occasional travel to client sites.

How we work

  • Short cycles. Automating a core client process in days, not quarters.
  • Determinism where it matters. Our clients have to explain every decision to a regulator. What can’t be audited doesn’t ship.
  • The agent executes, you answer for it. The code that goes into production is yours, whoever wrote it.
Apply

Apply for this role

Takes a couple of minutes. We read every application ourselves.

← All open roles Open role · Engineering

Software Engineer,
AI-Native (Full-Stack).

Madrid Hybrid Full-time 4–8 years

Design and build complete business applications, using AI agents as your normal way of working, for organizations that can’t give up control of their data.

Who we are

Airflows is an operational AI platform for regulated sectors. We turn documents, rules and approvals into real operations: private agents, auditable workflows and business applications that run under the client’s control, on their infrastructure, with no data leaving it.

We work with public administration, defense and security, banking and insurance, healthcare, utilities and industry. More than 45 clients already rely on the platform, across Spain and Latin America.

The promise we make to every client is simple and demanding: sovereignty over their data, their models and their intellectual property. Everything we build has to honour it.

The role

We’re looking for a software engineer with judgement of their own, who designs and builds complete business applications, and does so using AI agents as their normal way of working, not as an experiment.

Two things define the role:

  • You know how to build real software. You understand multi-layer architecture: presentation layer, business logic, data model, integrations. You know what goes where and why. You design a decent relational schema without being told, and you can tell when an API is badly designed.
  • You don’t develop the classic way. You work alongside AI agents to specify, generate, refactor, test and document. Your value isn’t in typing code, it’s in deciding what needs building, how it’s structured, and in ruthlessly validating what the agent produces.

We’re not looking for a junior profile or an ivory-tower architect. We’re looking for the engineer who sits down with a client, understands a business process, and within days has an application in production that the client actually uses.

Where you’ll build

We work in two contexts and you’ll move between both.

On the client’s technology stack. Many companies want to build their new developments with AI rather than the traditional way, but don’t yet have a platform that supports it. We come in with our own team and work on their technology: their language, their databases, their systems, their pipelines, their standards. What you bring there is the method, not the tool.

On the Airflows platform. When the client also needs to govern and operationalise their processes on AI models with traceability and control, we build on our own platform: agents, workflows, back-office applications and the governance layer.

For you, this is one of the most interesting parts of the job. In two years you’ll have seen from the inside how software gets built in several very different organizations, with real problems and real constraints. Very few people accumulate that perspective so fast.

What you’ll do

On any project

  • Sit down with the business, understand the process and translate it into an architecture that holds up.
  • Design and develop end-to-end applications: interface, business logic, data model and integrations.
  • Land in whatever stack is in front of you and be productive in days, using agents as leverage to navigate someone else’s code, understand it and extend it.
  • Integrate with the client’s systems of record (SAP, Oracle, Microsoft 365 and SharePoint, Salesforce, ServiceNow) via API and webhooks, without replatforming.
  • Deploy and operate in client environments: on-premise, private cloud, installations with connectivity restrictions.
  • Instrument what you build: if something fails in production, we need to see it before the client does.

On projects built on the Airflows platform

  • Complete back-office applications: forms, case queues, document viewers, dashboards.
  • Business processes modelled as workflows with SLAs, queues, approvals and deterministic routing.
  • Agents that classify, extract, draft and escalate, with human control points where the business demands them.
  • Field-level permissions, traceability and audit logs that stand up to a real regulatory inspection.

What we need from you

Essential

  • 4 to 8 years building production software, with ownership of what you shipped.
  • Solid backend (Java, Python, TypeScript or equivalent) and fluency in modern frontend (React or similar). We don’t ask for parity between the two, but you should be able to close a complete feature on your own.
  • Data modelling and SQL with judgement: normalisation, indexes, transactions, migrations.
  • REST API design and integration, authentication, error handling, idempotency.
  • Real, everyday use of AI agents in your development flow, with concrete examples of what you’ve built that way and where the approach failed you.
  • The ability to enter a stack you didn’t know and be useful fast. This matters more to us than deep mastery of one specific technology.
  • Direct client contact: knowing how to ask, how to say no, and how to hold a technical conversation in front of a head of IT.
  • Spanish and technical English.

Nice to have

  • Docker, Kubernetes, CI/CD and on-premise or air-gapped deployments.
  • Experience in regulated sectors: public administration, defense, banking, healthcare.
  • LLM orchestration, RAG, evaluation design and hallucination control.
  • Having worked face to face with business users, not just with tickets.

How we work

  • The agent executes, you answer for it. Using agents doesn’t dilute responsibility: the code you put into production is yours, whoever wrote it. Review, tests and security are not delegated.
  • Short cycles. Automating a core client process in days, not quarters. We iterate with the client in the room.
  • Determinism where it matters. We sell to clients who have to explain every decision to a regulator. What can’t be audited doesn’t ship.
  • Small team, high autonomy. Fewer layers, more judgement. If something is badly framed, you say so.

What this role is not

We’d rather filter this now than in the third interview:

  • It’s not a machine learning research or model training role. You won’t be fine-tuning or publishing papers.
  • It’s not data science or analytics.
  • It’s not a purely architectural role without touching code.
  • It’s not a single-technology role. If you’re after three straight years in the same framework, this isn’t the place.
  • It’s not a consultancy that places you with a client and forgets about you. You’re on the Airflows payroll, with a team, our own platform and an R&D line behind you, working on different projects according to what the company needs and what makes you grow.
  • It’s not an environment where AI-assisted development is optional or up for debate. It’s how we work.

What we offer

  • Salary range: according to demonstrable experience.
  • Working model: Madrid, with hybrid flexibility.
  • Direct, visible impact: your work is deployed in ministries, state security forces, large corporations and regional administrations.
  • Full access to whatever agent-assisted development tools you need.
  • Our own product in a market still being built, with room to influence how it’s built.

Selection process

  • Initial conversation (30 min).
  • Technical interview on architecture and design decisions (60 min), based on your own real projects.
  • A bounded practical exercise, with AI agents allowed and encouraged. We care about how you direct them, what you review and what you discard, more than the final result.
  • Final conversation with management.

Write to us with your CV or GitHub profile and two lines about the last thing you built with the help of agents.

Apply

Apply for this role

Takes a couple of minutes. We read every application ourselves.

Downloads area

Everything you need to get to know us.

Private, operational and governed AI, explained on paper. Dossiers, datasheets, brand kit and corporate material, ready to download.

Product Hub

Resources.

Brand

Logos & brand kit.

Airflows logo blanco
Logo: white
For dark backgrounds
Airflows logo negro
Logo: black
For light backgrounds

Need the full brand kit: colors and usage guidelines?

Open brand kit →

Can’t find what you need?

Brand kit

The Airflows brand kit.

Logos, colors and usage guidelines. Use them to represent Airflows consistently.

Logo

Download the logo.

Airflows logo blanco
Logo: white
For dark backgrounds
Airflows logo negro
Logo: black
For light backgrounds
Colors

The palette.

Ink#070809
Green#00FF6D
Blue#009DFF
Pink#F9006C

Black is the spine of the brand. The RGB accents (green, blue, pink) live inside the flow imagery and data, never as flat color walls.

Usage

Do & don’t.

✓Do

  • Keep clear space around the logo.
  • Use white logo on dark, black logo on light.
  • Let accent colors live inside imagery and data.

✕Don’t

  • Don’t recolor or distort the logo.
  • Don’t place the logo on busy backgrounds.
  • Don’t use accents as flat color walls.

Need something else?

Legal

Information Security Policy

Version 1.1 · Approved on 24/06/2026 · Public classification.

DocumentInformation Security Policy
Document typeRegulatory framework
ClassificationPublic
EntityAIR FLOWS DATA PLATFORM, S.L.
PurposeEstablish the security policy for information systems
Version1.1 · Approved by the Security Committee on 24/06/2026 (minutes No. 002)
ENS HIGH category badge
National Security Framework

Certified in conformity with the ENS, HIGH category

Issued by AENOR under Royal Decree 311/2022. Our information systems were audited and found compliant at HIGH category across all five dimensions (confidentiality, integrity, traceability, authenticity and availability) covering 73 security measures.

Certificate
ENS-2026/0138
Issued by
AENOR CONFIA S.A.U.
Valid until
21 September 2028
About our ENS certification →

1. Introduction

AIR FLOWS DATA PLATFORM, S.L., hereinafter AIRFLOWS, depends on information systems to achieve its objectives. These systems must be managed diligently, taking appropriate risk-based measures to protect them against accidental or deliberate damage that may affect the authenticity, traceability, integrity or confidentiality of the information processed, or the availability of the services provided.

The ultimate goal of information security is to ensure that the entity can meet its objectives, carry out its functions and deliver the services for which it was established, preserving the quality of information and the continued provision of services: acting in advance, supervising daily activity and reacting promptly to incidents.

ICT systems must be protected against rapidly evolving threats with the potential to affect the confidentiality, integrity, availability, intended use and value of information and services. Defending against these threats requires a strategy that adapts to changing environmental conditions. This means applying the minimum security measures required by the National Security Framework (ENS), continuously monitoring service levels, tracking and analysing reported vulnerabilities, and preparing an effective incident response.

AIRFLOWS must ensure that ICT security is an integral part of every stage of the system lifecycle, from conception to decommissioning, including development or procurement decisions and operational activities. Security requirements and funding needs must be identifiable and included in planning, requests for proposals and tender documents.

2. Scope

This policy applies to all AIRFLOWS information systems, to the people who make up the organization, and to AIRFLOWS service providers and ICT solution suppliers.

Information system classified as HIGH category under Royal Decree 311/2022.

3. Mission and objectives

At AIRFLOWS we define ourselves as a technology company specialized in the intelligent orchestration of operations through AI, developing a product made available to customers as SaaS and through various partners.

The security objectives that AIRFLOWS seeks to guarantee with this Policy are:

  • Guarantee the confidentiality, integrity and authenticity of information and continuity in the provision of services.
  • Implement risk-based security measures.
  • Train and raise awareness among AIRFLOWS members regarding information security.
  • Implement measures enabling access traceability and uphold the principle of least privilege, reinforcing users’ duty of confidentiality.
  • Deploy and control physical security, keeping information assets in secure areas protected by access controls.
  • Establish security in communications management, ensuring information transmitted over networks is adequately protected.
  • Control the acquisition, development and maintenance of systems throughout their lifecycle, ensuring security by default.
  • Control compliance with security measures in service provision and in the addition of new system components.
  • Manage security incidents for proper detection, containment, mitigation and resolution, adopting measures to prevent recurrence.
  • Protect personal information, adopting technical and organizational measures in accordance with data protection legislation.
  • Continuously monitor the security management system, improving and correcting detected inefficiencies.

4. Guiding principles

  • Strategic scope: information security must have the commitment and support of all levels of the entity and be coherently coordinated and integrated with other strategic initiatives.
  • Comprehensive security: security is understood as an integral process made up of all technical, human, material and organizational elements, avoiding one-off actions or ad-hoc treatment. It must be considered part of routine operations and applied from the initial design of ICT systems.
  • Risk-based management: security management based on identified risks maintains a controlled environment; measures shall be proportionate to the risk they address and must be justified, also taking into account personal data processing risks.
  • Prevention, detection, response and preservation: with preventive actions that minimise vulnerabilities and, when threats materialise, an agile response that restores information or services, guaranteeing secure preservation of information.
  • Lines of defence: the security strategy is designed and implemented in layers.
  • Continuous monitoring and periodic reassessment: means of detecting and responding to anomalous behaviour are implemented, along with continuous evaluation of asset security status and a continuous improvement process to review and update measures.
  • Security by default and by design: systems must be designed and configured to guarantee security by default, providing the minimum necessary functionality.
  • Segregation of responsibilities: the roles of Security Officer and System Officer shall be kept separate.

5. Regulatory framework

The main regulations affecting this Policy are:

  • Royal Decree 311/2022, of 3 May, regulating the National Security Framework (ENS).
  • Directive (EU) 2022/2555 (NIS2), on measures for a high common level of cybersecurity across the Union.
  • Regulation (EU) 2024/1689 (AI Act), laying down harmonised rules on artificial intelligence.
  • Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act).
  • Organic Law 3/2018, of 5 December, on Personal Data Protection and guarantee of digital rights.
  • Regulation (EU) 2016/679 (GDPR), on the protection of natural persons with regard to the processing of personal data.
  • Royal Decree 1007/2023 (Verifactu Regulation), on requirements for invoicing software systems.
  • Law 18/2022 (Crea y Crece Act), regulating mandatory electronic invoicing between companies and self-employed professionals.
  • Information security standards, in particular the latest versions of ISO/IEC 27001 and ISO/IEC 27002, as well as ISO/IEC 27034 (application security).

6. Security organization

Taking into account the articles set out in the ENS, the organization establishes the following actions to organize information security:

  • It shall appoint security roles: Service Officer(s), Information Officer, Security Officer, System Officer and Data Protection Officer.
  • It shall establish an advisory and strategic body for information security decision-making, called the Information Security Committee.

6.1. Information Officer (RINF) and Service Officer (RSERV)

  • Establish the security requirements applicable to information and services, within the framework of Annex I of the ENS Royal Decree, and may request a proposal from the Security Officer, taking into account the System Officer’s opinion.
  • Rule on access rights to information and services.
  • Accept residual risk levels affecting information and services.
  • Report to the Security Officer any change regarding the information and services under their responsibility, especially the addition of new services or information.
  • Holds ultimate responsibility for the use made of certain services and information and therefore for their protection.

6.2. Security Officer (RSEG)

  • Maintain and verify the appropriate level of security of the information handled and the services provided by the information systems.
  • Promote information security training and awareness.
  • Appoint those responsible for carrying out the risk analysis and the Statement of Applicability, identify security measures, determine required configurations and produce system documentation.
  • Approve the Statement of Applicability based on the security measures required under Annex II of the ENS.
  • Provide advice on determining the system category, in collaboration with the System Officer and the Security Committee.
  • Take part in preparing and implementing security improvement plans and, where applicable, continuity plans, validating them.
  • Manage external or internal system reviews and certification processes.
  • Submit system changes and other requirements to the Security Committee for approval.
  • Approve the security procedures forming part of the Regulatory Framework that fall outside the Committee’s remit, informing it of any changes made.
  • Participate in drafting the Information Security Policy within the Committee, for approval by Management.
  • Coordinate with the Secretary the calling of meetings, preparation of the agenda and drafting of minutes.
  • Is responsible for the direct or delegated execution of the Committee’s decisions.

6.3. System Officer (RSIS)

  • Develop, operate and maintain the information system throughout its lifecycle, producing the necessary operating procedures.
  • Define the topology and management of the system, establishing usage criteria and available services.
  • Halt access to information or provision of the service upon becoming aware of serious security deficiencies.
  • Ensure that specific security measures are properly integrated into the overall security framework.
  • Coordinate the functions of the system security administrator: management and updating of the hardware and software underpinning security mechanisms, and management of user authorizations and privileges, including activity monitoring.
  • Approve changes to the current system configuration and ensure that approved controls and procedures are strictly followed.
  • Supervise hardware and software installations, modifications and upgrades to ensure security is not compromised.
  • Monitor security status using event management tools and technical audit mechanisms.
  • Report any anomaly, compromise or vulnerability to the Security Officer and collaborate in investigating and resolving incidents.

6.4. Data Protection Officer (DPO)

  • Inform and advise the organization and those carrying out processing of their obligations under data protection legislation.
  • Monitor compliance with security regulations and internal data protection policies, including the assignment of responsibilities, staff awareness and training, and related audits.
  • Provide advice on data protection impact assessments and monitor their implementation.
  • Cooperate with the Spanish Data Protection Agency and act as its point of contact.
  • Analyse and verify the compliance of processing activities, advise on data protection by design and by default, and prioritise activities on a risk basis.

6.5. Information Security Committee

The Committee is made up of a Chair, a Secretary and Members, classified as permanent or non-permanent depending on whether their participation is mandatory.

  • Permanent members: Chair, Security Officer and System Officer.
  • Non-permanent members: Service Officers, Information Officer, Data Protection Officer, organizational representatives or external specialists whose presence is advisable, and advisors (with a voice but no vote).

The Data Protection Officer participates with a voice but no vote when matters concerning personal data are addressed; if an item is put to a vote, their opinion shall always be recorded in the minutes. The Secretary issues the notices of meeting and takes the minutes.

Role composition: Chair, CEO. Secretary, Head of Operations & Alliances. Members: CEO, CFO, CTO, Head of Product Engineering, CPO and Head of Operations & Alliances. System Officer: Head of Product Engineering. Security Officer: CPO. Data Protection Officer: external provider (Govertis).

Main powers: regularly report the state of security to Senior Management; promote continuous improvement of the Information Security Management System; develop the evolution strategy; promote periodic audits; approve security documentation; stay informed of ENS conformity certification regulations and accredited certification bodies; coordinate efforts across areas; resolve conflicts of responsibility; and review the Information Security Policy prior to approval by the governing body.

Frequency: the Committee shall meet at least once a year, without prejudice to greater frequency should needs require. Meetings are called by the Chair through the Secretary, on their own initiative or by a majority of permanent members. Decisions are taken by consensus of the permanent members.

6.6. Appointment and conflict resolution

  • The creation of the Committee, the appointment of its members and the designation of officers shall be carried out by means of an initial constitutive record.
  • Roles are renewed automatically each year. Departures or changes shall be reported to the Committee, following the established channels for appointing the new officer.
  • In accordance with Article 13.3 of the ENS Royal Decree, there may be no hierarchical dependency between the Security Officer and the System Officer, except in justified cases, which shall entail compensatory measures.
  • Where a conflict arises between security requirements and operational or business needs, any officer may escalate it to the Committee, which shall decide by consensus, with the decision documented in the minutes.
  • In situations of operational urgency where the Committee cannot be convened immediately, the Security Officer may adopt a provisional measure, documenting it and submitting it for ratification at the next session.

7. Personal data processing

AIRFLOWS processes personal data as described in the Record of Processing Activities. AIRFLOWS shall assess the risks relating to the personal data processed, proposing an action plan to correct any risks exceeding the authorised threshold.

The risk analysis shall be periodically reassessed, with the advice and supervision of the Data Protection Officer and, in any event, whenever high-risk processing is identified, carrying out an impact assessment where applicable. Implementation of the risk treatment plan shall be coordinated with that of the ENS, as shall other security procedures and standards with data protection obligations, especially in the oversight of service providers and the response to incidents and security breaches.

8. Risk management

All systems subject to this Policy shall carry out a risk analysis, assessing the threats and risks to which they are exposed. This analysis shall be repeated:

  • Regularly, at least once a year.
  • When there are changes in the information handled.
  • When there are changes in the services provided.
  • When a serious security incident occurs.
  • When serious vulnerabilities are reported.
  • When there are changes to the data protection risk analysis or impact assessments.

To harmonise risk analyses, the Security Committee shall establish a reference valuation for the different types of information handled and services provided, and shall facilitate the availability of resources to meet security needs, promoting horizontal investments. Data protection risks shall be taken into account, with the opinion of the Data Protection Officer, and risk treatment plans shall be coordinated.

The Statement of Applicability (SoA) sets out in detail the National Security Framework controls applicable to the information system of AIR FLOWS DATA PLATFORM, S.L., in accordance with Annex II of RD 311/2022, together with their applicability justification and maturity level.

9. Development of the Policy

This Policy shall be complemented by more specific documents (standards, security procedures and technical instructions) that help carry out what is proposed. The regulatory body is developed at three levels:

  • First level: this Information Security Policy.
  • Second level: the security standards derived from it, setting out the correct use of specific aspects of the management system.
  • Third level: security procedures, guides and technical instructions determining the actions or tasks to be performed in carrying out a process.

Approval of the Information Security Policy rests with management, while the Security Committee is the body responsible for approving and disseminating the remaining documents, as established in Article 12 of the ENS Royal Decree. Any change must be communicated to all affected parties.

10. Staff obligations

All AIRFLOWS members are obliged to know and comply with this Policy and the standards, procedures or guides that develop it. It is AIRFLOWS’ responsibility, through the Security Committee and the people area, to provide the means necessary for this information to reach those concerned.

All AIRFLOWS members shall attend an information security awareness session at least once a year. A continuous awareness programme shall be established, particularly for new joiners.

Those responsible for the use, operation or administration of ICT systems shall receive training in the secure handling of systems to the extent needed to perform their work. Training is mandatory before assuming a responsibility, both on first appointment and on a change of position or responsibility.

11. Third parties

Where AIRFLOWS provides services to other entities or handles information belonging to others, they shall be made party to this Policy, without prejudice to data protection obligations where it acts as processor, and channels shall be established for reporting and coordination between the respective Security Committees and for incident response procedures. The Security Officer (or their delegate) shall be the Point of Contact (POC).

Where AIRFLOWS uses third-party services or transfers information to third parties, they shall be made party to this Policy and to the Security Regulations applying to those services or information. When contracting service providers or purchasing products, the successful bidder’s obligation to comply with the ENS shall be taken into account. When acquiring usage rights over cloud assets, the requirements of Annex II and the development guides shall be observed.

Such third parties shall be subject to the obligations set out in those regulations and may develop their own operating procedures to satisfy them, so that AIRFLOWS can supervise them or request evidence of compliance, including second- or third-party audits. Specific incident reporting and resolution procedures shall be established, channelled through the POC of the third parties involved and, where personal data is affected, through the Data Protection Officer. Third parties shall ensure their staff are adequately security-aware, at least to the level established in this Policy.

Where any aspect of the Policy cannot be met by a third party, the Security Officer shall issue a report specifying the risks incurred and how to address them. This report must be approved by the Information and Service Officers concerned before contracting begins or, where applicable, before award.

Where the organization acquires, develops or deploys an artificial intelligence system, in addition to complying with the applicable regulations it must obtain a report from the Security Officer, who shall consult the Information and Service Officers and, where necessary, the System Officer; the Data Protection Officer shall also give their opinion.

12. Security incident management

AIRFLOWS shall have a procedure for the agile management of security events and incidents that pose a threat to information and services.

This procedure shall be integrated with others relating to security incidents under other sectoral regulations, such as personal data protection, in order to coordinate the response across different approaches and to notify supervisory authorities without undue delay and, where necessary, State law enforcement agencies or the courts.

13. Approval and entry into force

This Information Security Policy shall be effective from its date of approval until replaced by a new Policy.

The Policy shall be reviewed by the Information Security Committee at planned intervals not exceeding one year, or whenever significant changes occur, in order to ensure its continued suitability, adequacy and effectiveness.

Text approved on 24 June 2026 by the Security Committee and the corresponding minutes of AIRFLOWS, by signature of minutes No. 002.

Certification · September 2026

ENS certified,
HIGH category.

AENOR has certified that Airflows’ information systems comply with Spain’s National Security Framework at its highest level. For the organizations that work with us, it means their data and operations run on a platform audited to the standard required of the public sector.

But not only that. The certification also covers the development and deployment of enterprise applications with AI: the product we build, on our platform or on the client’s stack, is created under the same framework. A scope that very few AI companies hold certified.

ENS Certification of Conformity badge, HIGH category
Certificate
ENS-2026/0138
Category
HIGH
Security measures
73
Valid until
Sep 2028
What it is

The security standard of the Spanish public sector.

The National Security Framework (ENS), regulated by Royal Decree 311/2022, sets the principles and minimum requirements that information systems handling public-sector data must meet. It is mandatory for public administrations and for the companies that provide them with technology.

Systems are classified in three categories (basic, medium and high) according to the impact a security incident would have. HIGH is the most demanding: it applies where an incident could cause very serious damage, and it can only be proven through an independent audit by an accredited certification body.

Five dimensions

HIGH in every one of them.

C

Confidentiality

Only those authorized have access.

I

Integrity

Information cannot be altered without control.

T

Traceability

Every action is logged and auditable.

A

Authenticity

Identity is verified in every operation.

D

Availability

The service is there when operations need it.

Scope

What the certificate covers.

The information systems that support these services, at our Madrid headquarters.

  • Development and deployment of enterprise AI applications
  • Cloud technology platform (SaaS)
  • Support and maintenance services
  • Product operation and maintenance
  • Information security
  • Management, internal control and procurement
  • Legal services and contracting
  • Marketing and sales
Why it matters

Fewer barriers, more certainty.

Public tenders, unblocked

HIGH-category certification is a requirement in many public contracts. We already meet it.

Audited, not self-declared

An accredited third party verified our controls. It isn’t a promise: it’s evidence.

Consistent with our promise

Sovereignty over data, models and IP. The ENS certifies that the systems behind that promise are sound.

National Security Framework ENAC · ISO 17065 certification No.1/C-PR322
Certified by

AENOR CONFIA S.A.U., a certification body accredited by ENAC under ISO/IEC 17065 to certify conformity with the ENS. Audit report dated 15 September 2026; initial certification 21 September 2026, valid until 21 September 2028.

Download certificate (PDF)
Legal

Privacy Policy

Last updated: 16/11/2025.

At Air Flows Data Platform, S.L., we are committed to protecting the privacy and trust of our clients and potential clients. This policy details how we collect, use, store, protect, disclose, and manage your personal information (also known as personal data).

Our goal is to ensure maximum transparency and security in the handling of your information, strictly complying with current data protection legislation, including the General Data Protection Regulation (GDPR) in the European Union, the Organic Law on Personal Data Protection and guarantee of digital rights (LOPD GDD) in Spain, and other applicable regulations.

This policy applies to the processing of your personal information in connection with the use of our websites and applications that link to this Privacy Policy (collectively, the "Sites"), our products and services (the "Services"), and in the normal course of our business activities, such as events, sales, and marketing activities.

Scope of the Policy

This Privacy Policy is applicable to the personal information we collect, use, and process in connection with:

  • Our Websites and Applications: any website, mobile application, software, or other digital services that we own and that link to this policy.
  • Our Services (products and services): information processed when you contract or use our products and services.
  • Our Regular Business Activities: information collected in the context of events, trade shows, sales activities, marketing initiatives, webinars, and any other interaction we have with you.

Exclusions. This policy does not apply to data our clients upload to our platform services and that we process on their behalf (governed by the client agreement); to any product, service, website, or content offered by third parties with its own privacy policy; nor to information processed in connection with recruitment, covered by a separate candidate privacy policy.

Personal Information We Collect

Information You Provide to Us

  • Identifiers: full name, title, position, email address, phone number, postal address, country.
  • Professional/employment information: company name, industry, company size, position, role.
  • Account information: authentication information used to access the Services if you create an account.
  • Customer service and other interaction information: information collected when you interact and communicate with us (support, surveys, feedback, event registration, marketing), including records of communications, which may be stored as an audio file or transcript.
  • Commercial and financial information: purchase history and past transactions, and information about your designated payment method(s), which may be collected by third-party payment and billing providers.
  • Information posted in public forums: any information you post publicly will be visible to other users and potentially through search engines; be careful and do not provide personal information you do not want made available this way.

Information We Collect Automatically

We use standard automatic data collection tools, such as cookies, web beacons, tracking pixels, tags, and similar tools, to collect information about internet and device activity, as well as how people use our Sites and interact with our emails.

This may include information about your computer or device (operating system, device identifier, browser language, IP address) and about your activities on our Sites (how you arrived, access times, links you click, browsing behavior). We also collect "Usage Data" when you use the Services, to provide, support, secure and improve them. See our Cookie Policy for more detail.

Information We Receive from Other Sources

We may obtain information about you from third-party sources, including resellers, distributors, business partners, event sponsors, security and fraud detection services, social media platforms, and publicly accessible sources, and combine it with information we receive from you.

Purposes and Legal Bases for Data Processing

We use your personal information to provide, maintain, improve, and update our Services. The purposes and the legal bases that legitimize them are:

PurposeLegal basis (GDPR/LOPDGDD)
A. Provision of ServicesPerformance of a contract (Art. 6.1.b GDPR)
B. Commercial communication and marketingConsent (Art. 6.1.a GDPR)
C. Communication with youLegitimate interest (Art. 6.1.f) / Performance of a contract
D. Online advertisingConsent (Art. 6.1.a GDPR)
E. Personalization and improvement of ServicesLegitimate interest (Art. 6.1.f GDPR)
F. Legal and security purposesLegal obligation (Art. 6.1.c) / Legitimate interest
G. Administrative and financial managementPerformance of a contract / Legal obligation
H. Other purposes with your consentConsent (Art. 6.1.a GDPR)

For these purposes we may use tools such as large language models (LLMs) and other forms of artificial intelligence in accordance with applicable law. We may de-identify or anonymize information so it cannot reasonably identify you; our use of de-identified information is not subject to the restrictions of this policy.

How We Collect Data

  • Direct interactions: by phone, email, chat, in person (fairs, events, meetings), or by completing surveys and forms.
  • Our Websites and Applications: registration forms, newsletter subscriptions, demo requests, content downloads, or use of our online platforms.
  • Automatic data collection technologies: cookies, web beacons, tracking pixels and similar tools (see Cookie Policy).
  • Social networks and third parties: interactions on social media and data from partners, sponsors and publicly accessible sources, in accordance with regulations.

Data Recipients and International Transfers

We do not sell or rent your personal information to third parties for their own direct marketing without your explicit consent. We may disclose it to: service providers (data processors) who assist us (billing, payments, support, marketing, analytics, hosting, security), bound by confidentiality; partners and sponsors where a legal basis exists; for legal purposes; with your consent; and as part of business transactions.

Language detection by country. If you consent to measurement cookies, we determine the country of your connection in order to show the site in your language. To do so, your IP address is processed by one of these providers: ipwho.is or GeoJS (get.geojs.io). Only the country is stored, in your own browser, for 30 days; we do not keep your IP address. If you decline these cookies, no request is made to any provider and the language is determined solely by your browser settings.

International Data Transfers

We may transfer your information to countries other than your country of residence. Whenever we do, we apply appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and supplementary measures, to protect your data in accordance with applicable law.

Data Retention Period

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected and to address potential liabilities. The criteria are:

  • Clients: during the contractual relationship and, thereafter, the legally required periods (e.g. 5 years for personal actions; 6 years for accounting documentation).
  • Potential clients (leads): as long as business interest is maintained and consent is not revoked or the right to erasure is exercised.
  • Marketing purposes: until you revoke consent or object to the processing.
  • Legal obligations and fraud prevention: the time required by law and a reasonable period to detect and prevent fraudulent activity.

Once the retention period ends, data is securely deleted or anonymized, unless there is a legal requirement to keep it.

Security Measures

We implement technical, physical, and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction, including:

  • Data encryption in transit (SSL/TLS) and at rest where possible.
  • Access controls based on least privilege and identity management with multi-factor authentication.
  • Regular backups, monitoring and intrusion detection.
  • Security audits, staff training and confidentiality agreements.

However, no security measure is perfect or impenetrable, so we cannot guarantee the absolute security of your information.

Your Privacy Choices and Rights

As a data subject you have the rights of access, rectification, erasure (right to be forgotten), restriction of processing, portability, objection, to withdraw consent, and not to be subject to solely automated decision-making, as well as to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).

How to Exercise Your Rights

To exercise them, contact us through the channels in "How to Contact Us". We may require proof of your identity to verify you are the data subject; that information will only be used to process your request.

Opting out of marketing communications

You can opt out by following the unsubscribe instructions in each communication or by emailing support@airflows.com. We may still send you important service- or account-related communications.

Additional Important Information

Third-Party Services

Our Services may contain links to third-party websites, applications, services or social networks, or allow login with third-party credentials. Information you submit to those services is not covered by this policy; review their terms and privacy notices.

Children’s Data

The Sites and Services are not directed to children under 18, and we do not knowingly collect personal information from children under 18. If we learn we have collected such data, we will take steps to delete it.

Changes to the Privacy Policy

We may change this Privacy Policy from time to time. We will post changes on this page and, if substantial, provide a more prominent notice. If you do not agree with the changes, you must stop using the Services.

How to Contact Us

If you have any questions about our privacy practices or this Privacy Policy, contact us at support@airflows.com.

Postal address:
Air Flows Data Platform, S.L.
Carretera de Fuencarral, 56, Edif. Neogreen
28108 Alcobendas (Madrid), Spain

Legal

General subscription conditions

Last updated: 16/11/2025.

These subscription conditions are an inseparable part of the subscription contracted through the Order Form and will come into effect on the date of their signature between Airflows Data Platform SL. (Airflows) and the entity signing these General Conditions as identified in the Order Form (the "Client"). They may be referred to jointly as the "Parties" and individually as the "Party". To this end, Airflows and the Client agree to the following General Conditions:

1. Purpose

The purpose of the General Conditions is to establish the terms on the basis of which Airflows grants the "Beneficiary" (who may be the Client or a third party) a right of use subscription for the software it exclusively owns, Airflows Data Platform (the "Software"), in a Software as a Service (SaaS) modality.

2. Subscription

2.1. Rights

The Subscription granted under the Agreement provides the Beneficiary, during its term, with a non-exclusive and non-transferable right to access and use the Software in accordance with the General Conditions in its SaaS modality (hereinafter). The Beneficiary will exclusively have the right to access and use the Software, as well as the aforementioned Use Documentation, for its internal business purposes and under the conditions established in the Agreement and in the Use Documentation itself; which it undertakes to comply with at all times. Any other access and/or use of the Software will constitute a breach in accordance with the provisions of the Agreement.

Likewise, the Beneficiary undertakes to maintain the confidentiality of the Beneficiary's accounts, credentials, and any password necessary for accessing and using the Software, and will therefore be responsible for any use made of the Software through the Beneficiary's credentials or any account that the Beneficiary may establish. In case of loss, theft, suspicion of unauthorized use, or any other event that could affect the confidentiality of its accounts, credentials, or passwords, the Beneficiary must immediately notify Airflows so that it can take the necessary measures. Until Airflows is informed of such events, it will be exempt from all liability for operations that may be carried out using the Beneficiary's accounts, credentials, or passwords.

The Subscription allows the Beneficiary to remotely access and use the different functionalities and programs included under the Software via the Internet. This subscription includes management and operation services for the Cloud infrastructure on which the Software is installed.

Notwithstanding the foregoing, during the term of the Agreement, Airflows may perform the following actions:

  • Modify the systems and environment used to provide the subscription.
  • Reserve the right to make any change it deems necessary or useful to the Software to maintain or improve the quality or delivery of the services to its clients.

All support and maintenance operations on the Software to keep it operational in the contracted environment under optimal availability and performance conditions, through the incorporation of improvements developed in new versions, are included in the Subscription. Also, within the Subscription, Airflows will provide the Beneficiary with a service for monitoring, administration, and operation of the environment on which the Software is installed.

The acquisition of the Subscription includes Software updates, as well as bug fixes and hot-fixes, to keep the product operational in the environment contracted by the Beneficiary.

Through the subscription, the Beneficiary has the right to:

  • 8x5 support for logging cases (incidents and requests) related to the platform.
  • Technical support related to the installation and use of the platform.
  • Support from the contracted instance where platform documentation can be accessed.

This service will not include:

  • Support for applications developed on the platform.
  • Consulting services or any other services not expressly contracted.
  • The installation, configuration, and/or troubleshooting of third-party software.
  • The resolution of incidents or anomalies caused by improper use of the Software not adjusted to the previously indicated documentation, or by modifications to it not made or authorized by Airflows, including but not limited to: altering, modifying or damaging, totally or partially, the Software code without express authorization from Airflows, negligence in the use of the Software by the Beneficiary or improper use of it different from that initially foreseen or other causes beyond Airflows' control.

The Subscription also includes monitoring, administration and operation of environments that have the Software installed. This service includes the resolution of incidents related to the administration of the Software.

The support service is provided during business hours as described in this Clause.

The following services are included according to the service levels:

  • Monitoring (N1): Environment monitoring, attention and incident logging.
  • Operation (N2): Airflows expert personnel in the operation and administration of clusters with the software installed.
  • Systems (N3): Airflows expert personnel in the operation, administration and installation of Airflows instances.

The standard SaaS subscription includes an Airflows cloud instance with the following characteristics:

  • vCPUs: 2
  • Memory (GiB): 4
  • Outbound data transfer: 20Tb (€3/Tb additional)
  • Storage: 50Gb (€0.16/Tb additional)

The Use Documentation will be made available to the Beneficiary through a private URL. The Beneficiary is granted the right to make additional copies of the Use Documentation solely for internal use, which it undertakes to destroy once the Agreement has ended. The Beneficiary may not communicate, disclose or supply the Use Documentation to third parties outside the Beneficiary, except when strictly necessary for the proper development of this Agreement.

2.2. Beneficiary's Responsibilities

For the provision of any of the aforementioned supports, the Beneficiary will be responsible for:

  • The product has been managed and maintained in accordance with the best practices defined.
  • The product has not been modified.
  • Airflows is not responsible for third-party products not approved by Airflows.
  • If necessary, the Beneficiary will provide connectivity and necessary access for the correct performance of the Support Service's work.
  • The teams responsible for Software maintenance must be available for incident resolution if necessary.

2.3. Prohibitions

It is well understood that, by means of the Agreement, no right beyond the access and use described herein is granted to the Beneficiary. Thus, by means of the Subscription, the right of reproduction, distribution, public communication, or transformation of the Software, among others, are not granted. Therefore, the Beneficiary, unless expressly authorized by Airflows, shall not be entitled, among others, to (i) use the Software in any way that may cause damage, interruptions, inefficiencies or defects in its operation or in a third party's computer equipment; (ii) use the Software for the transmission, installation or publication of any virus, malicious code or other harmful programs or files; (iii) use the Software illegally, against good faith, morals and public order; (iv) access without authorization any section of the Software, other systems or networks connected to it, the Software servers, or the applications offered through the Software, by means of hacking or falsification, password extraction or any other illegitimate means; (v) break, or attempt to break, the security or authentication measures of the Software or any network connected to it, or the security or protection measures inherent in the contents offered in the Software; (vi) carry out any action that causes disproportionate or unnecessary saturation in the infrastructure, systems or networks of the Software, as well as in the systems and networks connected to the Software; (vii) violate the privacy rights of third parties or infringe intellectual property rights; (viii) reverse engineer the Software or attempt to reconstruct, identify or discover the source code or algorithms of said Software; (ix) transfer, sell, resell, sublicense, assign, rent, lease or distribute the Software, include it as a service or an outsourcing offer; (x) copy, adapt or reproduce any portion, feature, function or interface of the Software; or (xi) modify or incorporate the Software into another program with the aim of creating a derivative work thereof or of a part thereof. The Beneficiary will be responsible for complying with all terms of use of any software, content, service or website that it uploads, creates or accesses through the use of the Software.

2.4. Prohibition of access to third parties

The Beneficiary may not facilitate access, in whole or in part, to third parties to any of the functionalities and programs included under the Software, unless it has prior explicit written authorization from Airflows. In no case may such third party be a direct or indirect competitor of Airflows, and its access to the Software shall be limited to the Beneficiary's needs related to the Agreement.

Should the Parties exceptionally agree to a third party's access to the Software, in whole or in part, this third party must expressly accept these General Conditions and the specific applicable conditions, as well as sign the corresponding confidentiality agreement.

3. Duration

The Subscription has a duration established according to the "Order Conditions" of this document.

4. Billing and Payment Method

In the event that invoices are not paid within the established period, a monthly default interest of 1.5% or the maximum legal allowed will accrue from the due date until full payment. In the event that the Client does not pay the Subscription price within the aforementioned period, Airflows shall be entitled to: a) suspend the Subscription, without any liability on its part, until the Client settles the outstanding amount; or b) terminate the Agreement.

5. Representations and Warranties

5.1. The Parties mutually guarantee compliance with all the commitments they assume, and will indemnify each other against any damage, harm, expense, or penalty (including attorney's fees), in case of any judicial or extrajudicial claim by third parties (including regulatory bodies) for any cause linked to the rights and obligations arising from the Agreement, and will at all times assume the correct execution of its terms, being responsible to the other Party for this.

5.2. Airflows has developed the Software in accordance with international secure development standards, and has subjected it to security tests to detect possible vulnerabilities and reasonably protect it against malicious third-party attacks. However, like all computer programs, the Software may contain flaws. Airflows does not guarantee or assume responsibility for (i) the continuity of the Software's services and functionalities; (ii) the total absence of errors, anomalies and/or bugs in said Software, including its contents and/or functionalities; (iii) the usefulness of the Software for a specific purpose; or (iv) the damages or harms caused, to itself or to a third party, by any person who (a) infringes the conditions, rules and instructions that Airflows establishes in the Software or (b) violates the security systems of the Software or the systems from which it is distributed.

5.3. The Parties mutually guarantee that, at all times, they will be up to date with any applicable legal and payment obligations (including but not limited to: tax obligations, social security, etc.), exempting the other Party from any liability generated as a consequence of any judicial or extrajudicial claim by third parties for these concepts.

5.4. The breach of any of the foregoing warranties shall entitle the other Party to recover from the breaching Party any economic amount improperly assumed, including any possible administrative or judicial sanctions. In any case, the maximum liability that each of the Parties may incur for any cause vis-à-vis the other Party or third parties, arising from the Agreement, shall be limited to the amount of remuneration actually paid to Airflows for the Subscription during the twelve (12) months prior to the date of the event giving rise to the claim. However, the aforementioned limitation of liability shall not apply in cases of fraud, gross negligence or acts resulting in death or personal injury. Notwithstanding the foregoing, the Parties shall not be liable to the other Party for any consequential, indirect, punitive or exemplary damages of any kind, with respect to any claim related to the Agreement.

6. Termination

6.1. In addition to the legally established causes, the Agreement may be prematurely terminated due to the breach by either of the Parties of the material obligations assumed hereunder, provided that the Party requesting the termination has fulfilled its obligations and has previously required the breaching Party to comply with the unfulfilled obligation or obligations and, after thirty (30) days from the reception of such request, the breaching Party has not remedied said breach.

6.2. Likewise, the Parties shall be entitled to terminate the Agreement immediately in the event of (i) mutual agreement between the Parties; (ii) the extinction of the legal personality of either of the Parties, its entry into liquidation or any other situation that prevents the normal development of the purpose of the Agreement; and (iii) any other cause expressly contained in this Agreement or legally established by the current legislation at any time.

6.3. The termination of the Agreement shall entail the return by each of the Parties of any documents, data, reports, information and any other type of material that had been supplied to it by the other, and over which, by virtue of this Agreement, it had no right whatsoever. For its part, the Client must pay Airflows the amounts corresponding to the Agreement that have accrued up to the effective date of the termination of the Agreement. Likewise, the rights granted to the Client by means of the Agreement shall be immediately revoked upon its termination, preventing the latter from accessing and using the Software.

6.4. The early termination of the Agreement or the expiration of the established term or any of its extensions shall not give the Parties the right to compensation of any kind, except for damages that may be caused to the other party by fraud or fault.

7. Confidentiality

7.1. During the term of the Agreement, as well as after its termination for any cause, the Parties undertake to maintain strict confidentiality with respect to the content of this Agreement, as well as all information derived from its formalization.

7.2. Both Parties undertake to maintain strict confidentiality, not to use for their own benefit or that of third parties, nor to communicate, disclose or supply to any natural or legal person outside the other Party, either directly or indirectly, the secrets, knowledge, data, documents, methods, procedures and information in general, which refer to the business or finances of the other Party, its clients, its suppliers or its positions and employees, and of which they have knowledge by reason of the Services rendered in their favor, with the exception of those that are strictly necessary for the fulfillment of the obligations included in the Agreement. Notwithstanding the foregoing and unless expressly indicated by the Beneficiary, Airflows reserves the right to use the Beneficiary's name and logo in those media, materials and commercial documentation whose purpose is to demonstrate its experience in the market.

7.3. It is expressly stipulated that all documents, books, papers, notes, writings, contacts, information, etc., whether written or on magnetic, visual or computer media, provided by one of the Parties to the other within the framework of the Agreement, relating to its organization and to all natural or legal persons mentioned in the previous paragraph, shall be and shall always remain the property of the former, and must be returned or destroyed when so requested and, in any case, once the Agreement has expired.

7.4. The Parties undertake to give their executives, employees, agents, advisors and other related persons the guidelines and instructions they deem appropriate and convenient for the purposes of maintaining the secret, confidential and restricted nature of the information referred to in this Clause. Notwithstanding the foregoing, each of the Parties shall be directly responsible both for the conduct of its executives and/or employees and for the consequences that may arise therefrom in accordance with the provisions of this Clause.

7.5. The breach of the duty of confidentiality by either of the Parties shall give rise to the claim for damages caused by omission of said duty against the breaching Party.

8. Intellectual and Industrial Property

8.1. "Intellectual Property Rights" (hereinafter, "IPR") shall mean all intellectual property rights and industrial property rights (including without limitation those rights of a personal or economic nature such as copyright) that are recognized, now or in the future, by Spanish intellectual property or industrial property law or the laws of any applicable jurisdiction, including without limitation all inventions (and among them, inventions implemented in the IT sector with or without patent), patents, "utility models", industrial designs, semiconductor topography rights, registered or unregistered trademarks and service marks, reproduction rights, logos, presentation names and trade names, know-how (but only to the extent that the aforementioned may confer legal protection or license under applicable relevant legislation), domain names and goodwill linked to all of them, including in each case the ability (if any) (i) to apply for any necessary or simply convenient registration in order to obtain or protect such rights anywhere in the world and any registration thereof and (ii) to claim damages or any other remedy for the violation of such rights. IPR shall include without limitation those intellectual or industrial property rights duly registered before an official registry anywhere in the world, as well as registration applications and the rights to grant them and any right or form of protection of a similar nature in the world.

8.2. Each of the Parties owns and shall retain all IPRs over their respective industrial designs, patents, software, "utility models," databases, trademarks, logos, domain names, texts, images, and/or any other assets protected by intellectual and industrial property rights.

In particular, the Parties acknowledge that the Software and its various components, understood to include, by way of example, texts, photographs, graphics, images, icons, technology, know-how, software, links and other audiovisual or sound content, as well as its graphic design and source codes, are the exclusive property of Airflows, and no rights over them shall be deemed to have been assigned to the Beneficiary beyond the simple use licensed through the Agreement.

Likewise, all developments, improvements, changes, and new versions of the Software that Airflows may develop during the term of the Agreement shall also be the exclusive property of Airflows, which shall be subject, where applicable, to the terms and conditions of the Subscription granted by means of this Agreement.

8.3. In no case shall it be understood that, by virtue of this Agreement, each of the Parties grants the other Party an exclusive use Subscription of the intellectual and industrial property with which each markets its products and services.

8.4. The Parties agree to limit Airflows' liability for any event arising from IPR infringements to a maximum global amount equivalent to the net amount received by Airflows in payment of the Subscription during the twelve (12) months prior to the corresponding infringement.

9. Access to Data on Behalf of the Beneficiary

9.1. In the event that, in the development of this Agreement, Airflows provides any service to the Beneficiary that involves the access and processing of personal data, Airflows shall be considered a "Processor" and undertakes to take all necessary measures to guarantee the protection of personal data under the responsibility of the Beneficiary ("Controller").

9.2. The contracted Subscription could imply the Processor carrying out at least the following processing operations: collection, recording, consultation, storage, dissemination, modification and deletion of personal data. In the event that the Subscription implies the collection of personal data, the Processor will comply with the duty to inform in accordance with the instructions provided by the Controller.

9.3. Purpose of processing

Personal data will be processed, solely, to carry out the provision of the Subscription. If the Processor considers it necessary to carry out data processing for a different purpose, it must first request written authorization from the Controller. In the absence of such authorization, the Processor may not carry out said processing.

9.4. Types of data processed and categories of data subjects

9.4.1. The types of personal data that the Processor will process under this Agreement are the following:

  • Identifying data: name and surname, NIF/DNI, Social Security/Mutual Society affiliation number, address, telephone, signature, fingerprint, image/voice, physical marks, electronic signature, other biometric data.
  • Personal characteristics data: marital status, family data, date of birth, place of birth, age, sex, nationality, mother tongue, physical or anthropometric characteristics.
  • Social circumstances data: accommodation/housing characteristics, properties or possessions, hobbies and lifestyle, membership of clubs or associations, licenses, permits or authorizations.
  • Academic and professional data: training/qualifications, student history, professional experience, membership of professional associations or colleges.
  • Employment details data: profession, job position, non-economic payroll data, employee history.
  • Commercial information data: activities or businesses, commercial licenses, subscriptions to publications or media, literary, artistic, scientific or technical creations.
  • Economic, financial and insurance data: income and revenues, investments and assets, credits, loans and guarantees, bank data, pension and retirement plans, economic payroll data, tax deductions and taxes, insurance, mortgages, subsidies and benefits, credit history, credit card.
  • Data on transactions of goods and services: goods and services supplied by the data subject, goods and services received by the data subject, financial transactions, compensation and indemnities.
  • Health or disability data.
  • Trade union affiliation, religion, beliefs or data related to sexual life. Biometric data.
  • Data relating to criminal offenses.

9.4.2. The categories of data subjects whose data will be processed by the Processor under this Agreement are the following:

  • Clients.
  • Potential Clients.
  • Suppliers.
  • Contact persons.
  • Employees.
  • Candidates in personnel selection processes.
  • Persons whose images are captured by video surveillance systems.

9.5. Controller's Obligations

  • To make available to the Processor the personal data and/or necessary information for the proper processing of the same for the Subscription.
  • To carry out an assessment of the impact on the protection of personal data of the processing operations to be carried out by the Processor.
  • To carry out the necessary prior consultations to guarantee correct regulatory compliance and mitigate associated risks.
  • To ensure, prior to and throughout the processing, compliance with the GDPR by the Processor.
  • To supervise the processing, including carrying out inspections and audits.

9.6. Processor's Obligations

  • To process personal data solely for the purpose of providing the contracted Subscription, adhering to the instructions provided in writing by the Controller at all times (unless there is a regulation that obliges complementary processing, in which case, the processor will inform the controller of this legal requirement prior to processing, unless such law prohibits it for important reasons of public interest).
  • To maintain the duty of secrecy regarding personal data to which it has access, even after the contractual relationship has ended, as well as to ensure that its personnel have committed in writing to maintaining the confidentiality of the personal data processed.
  • To guarantee, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as risks of varying likelihood and severity for the rights and freedoms of natural persons, that it will apply appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which may include, among others:
    • The pseudonymisation and encryption of personal data.
    • The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
    • The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.
    • A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

    When assessing the adequacy of the security level, particular account shall be taken of the risks that are presented by the processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.

  • To keep under its control and custody the personal data to which it accesses due to the provision of the Service and not to disclose, transfer, or otherwise communicate them, not even for their conservation, to other people outside of it and the provision of the Service subject to this Agreement.

    However, the Processor may resort to another Processor (hereinafter, the Sub-processor) of its group. In the event that the Processor wishes to incorporate a new Sub-processor that was not part of the group at the time of signing these presents, it will provide the Beneficiary with the corresponding identifying data (full company name and NIF) and subcontracted services before the provision of the service, with a minimum notice of one (1) month. The controller will have the opportunity to object to such changes with justification. In such case, if the Processor could not provide its services without the Sub-processor in question, the Controller may request the termination of the contract without penalty for this reason.

    In case of making use of the faculty recognized in the previous paragraph, the Processor is obliged to transfer and communicate to the Sub-processor the set of obligations that for the Processor derive from this Agreement and, in particular, the provision of sufficient guarantees that it will apply appropriate technical and organizational measures, so that the processing complies with the applicable regulations.

    In any case, access to data by natural persons who provide their services to the Processor acting within its organizational framework by virtue of a commercial and not labor relationship is authorized. Likewise, access to data by companies and professionals that the Processor has contracted in its internal organizational scope to provide general or maintenance services (IT services, advice, audits, etc.), as long as these tasks have not been agreed upon by the Processor with the purpose of subcontracting all or part of the Subscription provided to the Controller, is authorized.

  • To delete or return to the Data Controller, at its discretion, all personal data to which it has had access to provide the Service. Likewise, the Data Processor undertakes to delete existing copies, unless there is a legal norm that requires the retention of personal data. However, the Data Processor may retain the data, duly blocked, as long as responsibilities may arise from its relationship with the Data Controller.
  • To notify, by means of an encrypted email or other secure transmission means, the Controller, as soon as it becomes aware of the existence of any security violation or breach that causes the destruction, loss or illicit alteration, loss and alteration, unauthorized disclosure or access, of personal data transmitted, stored or otherwise processed or unauthorized communication or access to such data. This notification will include the information required in Article 33 of the GDPR.

    In addition, the Processor undertakes to support the Controller in case notification to the Spanish Data Protection Agency and, where appropriate, to the data subjects of the security breaches that occur, as well as to support it, when necessary, in carrying out privacy impact assessments and in prior consultation with the Spanish Data Protection Agency, when appropriate, as well as to assist the Controller so that it can comply with the obligation to respond to requests for the exercise of rights.

  • To maintain, in writing, a record of all categories of processing activities carried out on behalf of the Controller.
  • To cooperate with the Spanish Data Protection Agency or other Supervisory Authority, at its request, in the exercise of its powers.
  • To make available to the Controller all information necessary to demonstrate compliance with the obligations established in this Agreement and to allow and contribute to the performance of audits, including inspections, by the Controller or a third party authorized by it. The failure to prove that the Processor is correctly complying with the obligations assumed in this Agreement will be cause for termination thereof.

The Processor guarantees that, in relation to the execution of the Agreement, no processing of personal data will be carried out outside the European Economic Area (EEA) or in a country that does not have an adequate level of protection. In case of transfer of personal data to a third country not belonging to the EEA, or an international organization, the Processor must obtain prior written authorization from the Controller and cooperate with it to guarantee an adequate protection framework under current regulations, through the application of binding corporate rules, the formalization of standard contractual clauses adopted by the European Commission or, where appropriate, obtaining authorization for the transfer from the competent authority.

If the Processor or any of its Sub-processors infringes this Agreement or any regulation when determining the purposes and means of processing, it will be considered responsible for said processing.

10. Relationship Between the Parties

10.1. Given the characteristics of the content of the obligations assumed under this Agreement, the Parties expressly acknowledge the commercial nature of the relationship that links them through this Agreement, as well as their absolute independence and autonomy, there being no relationship of dependence or subordination between them, nor between each of the Parties and the dependents or subordinates of the other Party.

10.2. Consequently, nothing in this Agreement shall be interpreted as (i) the constitution of a company, agency, joint venture, or a similar relationship between the Parties; (ii) as an authorization to either of the Parties to represent, or act as an agent or employee of the other Party; or (iii) the existence of any type of employment relationship between them.

11. Force Majeure

11.1. The Parties shall not incur liability for the breach of their obligations established in this Agreement, or of any other obligation that derives from the contractual relationship, when the breach occurs as a consequence of a fortuitous event or force majeure.

11.2. Fortuitous event or force majeure shall be understood as any event beyond the will of the Parties, foreseeable or unforeseeable but unavoidable and insurmountable in itself or in its consequences, which is not a result of their fault or negligence, provided that they have not contributed to the event occurring.

11.3. Contractual obligations whose fulfillment is prevented by a fortuitous event or force majeure shall not be enforceable for either of the Parties only during the time that such impediment subsists. As soon as the impediment ceases, the enforceability of the fulfillment of said obligations shall be re-established. In addition, the presence of a fortuitous event or force majeure shall exempt from the responsibility of paying damages for the delay in the fulfillment of the obligations whose enforceability had been suspended. In such case, the Parties shall act with the utmost diligence to mitigate, remedy or overcome its effects.

11.4. Events of fortuitous event or force majeure may include, but are not limited to, hurricanes, earthquakes, floods, fires, declared or undeclared wars, insurrections, terrorist acts and sabotages.

11.5. In the event that a force majeure or fortuitous event persists for more than thirty (30) days, either Party may, upon written notice to the other Party, terminate this Agreement.

12. Prohibition of Assignment

12.1. The assignment or transfer, regardless of the form or legal transaction used for this purpose, of the rights and obligations assumed by any of the Parties in this Agreement, may only be carried out with the express written agreement of the same.

12.2. The assignment or transfer of this Agreement, or any part thereof, contrary to the provisions of this Clause, shall be considered invalid and void.

13. Notifications

13.1. The Parties accept email as a valid means for the flow and exchange of documentation, information and, in general, as a communication channel between them for the purposes of this Agreement. Each of them exempts the other from liability for the interception or access to emails by unauthorized persons, as well as for any damage or harm that may be caused to the other Party as a result of computer viruses, network failures or similar circumstances, unless it is for a cause attributable to the other Party. It shall be understood that communications by email have been duly notified to the other Party when they are effectively received legibly by the latter, provided that the sender does not receive an email communicating the error or the impossibility of notification (delivery failure notification). Any email communication sent after 5 p.m. in the destination city shall be deemed to take effect on the first business day thereafter in said place.

13.2. Each Party states that the email addresses listed in the Order Form as notification addresses are and will be their property, undertaking to provide the other Party with sufficient justification if the latter requires it. In the event of a dispute, the Parties may not object to the existence of a communication sent via email, when the provisions of this Clause have been complied with.

14. Partial Nullity

In the event that any of the Clauses or obligations of this Agreement are declared null or illegal, the Parties undertake to maintain the contractual relationship in consideration of the rest and globality thereof, integrating or correcting the effects of said nullity or illegality as far as possible, and except for manifest and irresolvable disproportion between the obligations and considerations to be assumed by any of the Parties.

15. Enforceability

The failure by any Party, at any time, to demand compliance by the other Party with any stipulation of this Agreement shall in no way affect the right of said Party to assert the same at a later time, nor to assert any of the other stipulations of this Agreement; nor shall the waiver by any Party to denounce the breach of any stipulation of this Agreement be understood or interpreted as a waiver to denounce any subsequent breach of said stipulation or as a waiver of the stipulation itself.

16. Applicable Law and Jurisdiction

16.1. For everything not provided for in this Agreement, the Spanish legislation in force at all times shall apply.

16.2. For any matter that may arise from the interpretation or application of this Agreement, both Parties, by mutual agreement, expressly submit to the jurisdiction of the Courts of Madrid capital, expressly waiving any other jurisdiction that may correspond to them.